1.1 Who we are
This Privacy Policy describes how ViewNest ("we", "us", "our"), the operator of the ViewNest mobile application (the "Service"), collects, uses, and protects personal information.
If you have any questions about privacy, you can contact us at:
- Email: viewnest7@gmail.com
ViewNest is operated from Canada. We process data on infrastructure located in the United States and (for some user locations) in the European Union.
1.2 Who has an account on ViewNest
ViewNest accounts are intended for parents or legal guardians aged 18 or older. Children do not create accounts of their own and never enter personal information into the Service. The parent is the data subject for purposes of this policy. Where children watch videos through the parent's curated library, they do so under the supervision and control of the parent who set up the account.
1.3 Personal information we collect
We collect only the data we need to operate the parent-controlled video service. Specifically:
| Category | What it is | When we collect it | Source |
|---|---|---|---|
| Authentication identifiers | Stable user ID issued by Google or Apple ("sub"), provider name, email address, display name (if you choose to share it) | When you sign in with Google or Apple | You / your identity provider |
| Session data | Random per-device access token, device identifier (a random ID generated by the app the first time it runs — not your phone's hardware ID), platform name (iOS / Android), last-active timestamp | When you sign in on a device | Your device |
| Subscription data | RevenueCat subscriber/entitlement reference, the purchased product (monthly or yearly), current period end, free-trial start and end dates, payment status (active / past due / cancelled). Payment is processed by the Apple App Store or Google Play — we never receive card numbers. | When you start a trial or subscribe | Your interactions; RevenueCat / App Store / Google Play notifications |
| App library | YouTube video IDs and channel/playlist references that you choose to add, plus the metadata (title, thumbnail, duration, channel name) we fetch from YouTube to display them | When you save videos | You + YouTube Data API |
| Watch activity | Video IDs played and watch duration, used to enforce the screentime, minimum-watch-time, and continue-watching features | When a video plays in the app | Your device |
| Account-level operational data | YouTube API quota units used per day, signed-in device count, account deletion requests | Continuously while the Service is in use | Your device + our backend |
| Diagnostic logs | Server-side request logs (HTTP method, path, status code, duration, generic error messages, IP address kept transiently for abuse prevention) | Each API call | Our infrastructure (Render) |
| PIN code | A 4-digit numeric code you set to lock the parent dashboard | When you set or change the PIN | You |
We deliberately do not collect: ad identifiers, contact lists, location, photos, microphone, biometrics, browsing history outside the app, or any data from the child user. The app does not contain Facebook SDK, Firebase Analytics, or any other behavioural-analytics tracker.
1.3.1 Where the PIN is stored
The parent dashboard PIN is stored on your device only (in iOS Keychain or Android EncryptedSharedPreferences via flutter_secure_storage). It is never transmitted to or stored on our servers.
1.3.2 Information we do not receive
When you sign in with Apple's "Hide My Email" option, you receive a private relay address. We store that relay address as your email; we never see your real Apple ID email and have no way to message you outside the relay.
1.4 Why we collect each category, and the legal basis (GDPR Article 6)
| Purpose | Categories used | Legal basis |
|---|---|---|
| Create and authenticate your account | Authentication identifiers, session data | Contract (Article 6(1)(b)) — necessary to provide the Service you signed up for |
| Provide the curated YouTube viewing service to your child | App library, watch activity | Contract (Article 6(1)(b)) |
| Process subscription payments | Subscription data | Contract (Article 6(1)(b)); also legal obligation for tax records |
| Enforce the device limit (max 3 devices per account) | Session data | Legitimate interests (Article 6(1)(f)) — preventing abuse of the subscription |
| Enforce the per-account YouTube API quota cap | Account-level operational data | Legitimate interests — sustainable infrastructure cost |
| Diagnose bugs and prevent abuse | Diagnostic logs | Legitimate interests |
| Comply with legal requirements (tax, lawful requests) | Subscription data, diagnostic logs | Legal obligation (Article 6(1)(c)) |
We do not use your data for advertising, profiling, or marketing communications. We do not sell or rent personal data.
1.5 Third-party services we share data with
| Service | What we share | Why | Their privacy policy |
|---|---|---|---|
| Google LLC (Sign-In, YouTube Data API v3, YouTube embedded player) | Your sign-in token (Google flow only) and YouTube video/channel IDs are sent to Google to verify identity and fetch metadata. The embedded YouTube player loads videos from Google's servers and may receive your IP and device information when a child watches. | Authentication; serving YouTube content. The embedded player is governed by YouTube's Terms and Google's Privacy Policy. | policies.google.com/privacy |
| Apple Inc. (Sign in with Apple) | Your Apple identity token (during sign-in only) | Authentication | apple.com/legal/privacy |
| Apple App Store / Google Play (Payments) | Your purchase and payment details are handled directly by Apple or Google through in-app purchase — we never see or store your payment method or card numbers | Subscription billing | apple.com/legal/privacy · policies.google.com/privacy |
| RevenueCat, Inc. (Subscription management) | Your account ID, the purchased product, and subscription/entitlement status (purchase receipts are validated by RevenueCat with Apple/Google) | Validating purchases and tracking subscription state | revenuecat.com/privacy |
| Render Services, Inc. (Backend hosting) | All API request and database content (transit + at-rest hosting) | Compute and storage | render.com/privacy |
| Supabase, Inc. (Database hosting) | Database content (your account record, library, sessions, billing events) | Persistent storage | supabase.com/privacy |
We share only what each provider needs to perform its function. Each is bound by its own privacy obligations, and (where applicable) by a Data Processing Agreement that we have entered into.
We do not sell personal information to advertisers, data brokers, or any other third party.
1.6 Children and YouTube content
1.6.1 Our scope
ViewNest is a parental-control service. The parent decides which videos a child may watch. We do not collect personal information from children. Any in-app activity captured (e.g. how many seconds of an approved video were watched) is associated only with the parent's account, not with a named child profile.
1.6.2 YouTube embed disclaimer
ViewNest plays approved videos through the official YouTube IFrame Player API. When a video plays:
- Google receives technical information (your IP address, the device user agent, and the video ID) so it can deliver the video.
- YouTube may display ads inside or before the video (subject to your YouTube account's settings or, for unauthenticated viewers, default ad behaviour).
- YouTube's own data practices, including any ad personalisation, are governed by Google's Privacy Policy and the YouTube Terms of Service.
We do not modify, intercept, or block any advertisement, control, frame, watermark, or branding rendered by the embedded YouTube player. Advertisements served by YouTube are rendered as YouTube delivers them.
We have no control over and no insight into what data Google collects through the YouTube player. We recommend that parents review YouTube's privacy practices before letting young children use any embedded YouTube content, including ours.
1.6.3 COPPA (US) statement
ViewNest is not directed at children under 13 as a "kids product" in the COPPA sense. The user (parent) is over 13 and creates and controls the account. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information directly to us through any channel (e.g. via the support email), please contact us and we will delete it promptly.
1.6.4 GDPR-K and similar laws
For users in jurisdictions that require parental consent for processing children's data (GDPR's Article 8 in the EU, the UK Age-Appropriate Design Code, India's DPDP Act 2023 minor provisions), the parent's act of curating videos and enabling viewing for the child constitutes the parental consent for the limited child-side processing the Service performs (i.e. the watch-activity tracking described in §1.3).
1.7 How long we keep data
| Data | Retention |
|---|---|
| Active account record (auth identifiers, library, sessions, settings) | Until you delete your account |
| Subscription / billing records | Up to 7 years after subscription ends, to satisfy tax and audit obligations in the operating jurisdiction |
| Watch activity | Up to 12 months, then aggregated or deleted |
| Diagnostic logs | 30 days |
Webhook event log (billing_events) | 24 months for fraud and dispute resolution |
Account deletion requests are processed within 30 days of receipt.
1.8 Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Delete your account and personal information ("right to be forgotten" in the GDPR / "right to erasure" in CCPA)
- Port your data to another service in a machine-readable format
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
- Lodge a complaint with your local data protection authority (e.g. ICO in the UK, your DPA in the EU, the Privacy Protection Authority in your country)
To exercise any of these rights:
- In the app → Parent settings → "Request account deletion" — this is the fastest path for full deletion.
- By email → write to viewnest7@gmail.com from the email address associated with your account.
We respond within 30 days. We never charge a fee unless your request is manifestly unfounded or excessive (in which case we'll explain the basis before charging).
1.9 California, Virginia, Colorado, Connecticut, Utah residents
You have the rights described above plus the right to opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of, but we acknowledge your right.
We do not use sensitive personal information (such as racial or ethnic origin, religious beliefs, biometric data, etc.) for any purpose. We do not knowingly collect data from minors under 16 without parental consent.
1.10 International data transfers
We are based in Canada. Our service providers (Apple, Google, RevenueCat, Render, Supabase) operate primarily in the United States. If you are located in the EU/UK or other jurisdictions with cross-border data transfer rules, your personal data may be transferred to and processed in the United States. Where such transfers are made, we rely on the European Commission's Standard Contractual Clauses or each provider's published transfer mechanism (e.g. Google's SCCs).
1.11 Security
We protect personal data with:
- Transport security (HTTPS) for every connection between the mobile app and our backend — cleartext HTTP is disabled in release builds of the Android app.
- Verified identity tokens — your sign-in is validated against Google's and Apple's published public keys (JWKS) on every login; we never accept a self-asserted email.
- Per-device session tokens with limited surface area: each device gets its own access token, evictable from any other signed-in device.
- Restricted API keys for third-party services (e.g. our RevenueCat key has the minimum permissions required).
- Hashed-of-random secrets — your sign-in nonce is SHA-256 hashed before being stored, so a database leak does not expose nonces.
- Encrypted on-device storage for the parent PIN (Keychain on iOS, EncryptedSharedPreferences on Android).
- Database hosted by Supabase with TLS for connections and encryption at rest.
No method of electronic storage is 100% secure. If we ever discover a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant authority within the timelines required by applicable law (e.g. 72 hours under the GDPR).
1.12 Cookies and similar technologies
The ViewNest mobile app does not use cookies. The web pages we serve (/privacy, /terms) do not set any cookies.
Subscriptions are purchased through the Apple App Store or Google Play in-app purchase sheet. No payment web page is opened by the app, and we set no payment cookies.
When the YouTube embedded player plays a video inside the app, YouTube/Google may set storage that the player relies on. That storage is governed by Google's privacy policy.
1.13 Account deletion
You can delete your account at any time:
- From inside the app: Parent settings → Help & legal → Request account deletion.
- By email to viewnest7@gmail.com from the address on the account.
Deletion removes your account record, your library, your sessions, and your subscription record from our active database within 30 days. Aggregated, non-identifying analytics may be retained. Records we are legally required to keep (e.g. tax invoices) are retained for the period the law requires and then deleted.
Your purchase history is held by the Apple App Store or Google Play and by RevenueCat under their separate policies. To manage or cancel your subscription, use your device's subscription settings (App Store or Google Play). To request deletion of records held by those providers, contact them directly or contact us and we'll relay the request.
1.14 Changes to this policy
We may update this policy when we add features, change service providers, or to comply with new legal requirements. When we make material changes we will:
- Update the "Last updated" date at the top.
- Notify you in-app the next time you open the parent dashboard.
- For substantial changes (e.g. a new category of data, a new third-party recipient), give you at least 14 days' notice before the changes take effect.
If you do not agree with the changes, you may delete your account at any time before they take effect.
1.15 Contact
For any privacy question or to exercise any right described above, contact:
- Email: viewnest7@gmail.com